ZeroHour

CVE-2026-19586

PoC large

Pre-auth OS command injection in TP-Link Omada gateways via OpenVPN Server

CVSS 4.0
9.3 critical
EPSS
6%p93
Published
()
Modified
AI analysis

CVE-2026-19586 is a pre-authentication OS command injection flaw (CWE-78) in TP-Link Omada business gateways when they are configured to operate as an OpenVPN Server, caused by insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker who can reach the VPN service can send specially crafted input during a connection attempt to influence backend command execution before authentication completes, gaining arbitrary command execution and potentially full compromise of the gateway, which typically sits at the network edge controlling routing and VPN for the whole site. Affected organizations are those running any of the listed Omada gateway models with the OpenVPN Server feature enabled and reachable by the attacker. TP-Link rates the issue critical (CVSS 4.0 base score 9.3). A public technical write-up/PoC exists and EPSS assigns a 5.7% probability of exploitation within 30 days (93rd percentile), but exploitation has not yet been confirmed in the wild and the flaw is not in CISA KEV.

What to do: Update all listed Omada gateway models to the latest firmware per TP-Link's security advisory (fixed version numbers are not specified in the available data, so check the advisory for affected/fixed ranges). Until patched, disable OpenVPN Server or restrict access to the VPN service (e.g., firewall/ACL rules limiting UDP 1194 to trusted sources). Inventory your estate for these gateway models, confirm whether OpenVPN Server is enabled and reachable, and review VPN logs for anomalous connection attempts.

Affected
TP-Link Omada ER7212PC gateway firmware
TP-Link Omada ER605 gateway firmware
TP-Link Omada ER605W gateway firmware
TP-Link Omada ER7206 gateway firmware
TP-Link Omada ER7406 gateway firmware
TP-Link Omada ER707-M2 gateway firmware
TP-Link Omada ER7412-M2 gateway firmware
TP-Link Omada ER8411 gateway firmware
TP-Link Omada ER706W gateway firmware
TP-Link Omada ER706W-4G gateway firmware
TP-Link Omada ER706WP-4G gateway firmware
TP-Link Omada ER703WP-4G-Outdoor gateway firmware
Estimated exposure
large~10,000-100,000 internet-exposed OpenVPN-enabled gateways, out of a much larger deployed base of these SMB gateway models — Estimated from the wide deployment of TP-Link's Omada SMB gateway line (the ER605 and ER7206 are among the most commonly deployed SMB VPN routers) scaled down by the subset of sites that enable OpenVPN Server and expose the VPN service to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt. Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

Vendors
tp-link
Products
er7212pc firmware, er605 firmware, er605w firmware, er7206 firmware, er7406 firmware, er707-m2 firmware, er7412-m2 firmware, er8411 firmware, er706w firmware, er706w-4g firmware, er706wp-4g firmware, er703wp-4g-outdoor firmware
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.